CVE-2026-9066
WP Compress < 7.10.04 - Reflected XSS via test_zone
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.
| Vendor | unknown |
| Product | wp compress |
| Published | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp compress
Be the first to know when new unknown vulnerabilities affecting unknown wp compress are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Compress
0 < 7.10.04
References
Credits
Lubin Regnault WPScan